Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 8 Jul 2002 13:09:01 -0700
From:      faSty <fasty@i-sphere.com>
To:        twig les <twigles@yahoo.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: hiding OS name
Message-ID:  <20020708200901.GB94197@i-sphere.com>
In-Reply-To: <20020708195244.79411.qmail@web10107.mail.yahoo.com>
References:  <20020708183726.GA363@straylight.oblivion.bg> <20020708195244.79411.qmail@web10107.mail.yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Yeah, I know. but it still Denial of Service with spoofing hit
hard on portsentry.

-fasty

On Mon, Jul 08, 2002 at 12:52:44PM -0700, twig les wrote:
> Nah, they have an ignore file of IPs to never block. 
> rude but simple and effective.
> 
> 
> --- Peter Pentchev <roam@ringlet.net> wrote:
> > On Mon, Jul 08, 2002 at 02:13:42PM -0400, Klaus
> > Steden wrote:
> > > > Portsentry may help
> > (/usr/ports/security/portsentry I
> > > > believe).  Won't hide the OS, but it may shut
> > down
> > > > scans before they get that far.  <shrug>, never
> > tested
> > > > it that way.
> > > > 
> > > A friend of mine runs portsentry configured to
> > blackhole every IP that
> > > attempts to connect to a port where no server is
> > running (in conjunction with
> > > a strict firewall); that can be done in FreeBSD
> > without using portsentry, via
> > > the blackhole sysctl MIBs. See blackhole(4).
> > > 
> > > It's not a bad means to keep people out of your
> > machines.
> > 
> > I know I'm going to regret posting in this thread,
> > but so be it :)
> > 
> > Does your friend know that, unlikely as it is made
> > by modern ingress and
> > egress routing practices, IP spoofing is still not
> > quite ruled out?
> > Will your friend's portsentry setup happily
> > blackhole e.g. his ISP's
> > nameserver, or the root nameservers, or
> > www.cnn.com's IP addresses,
> > simply because somebody found a way to send a TCP
> > SYN packet with a
> > forged source address to e.g. your friend's
> > machine's port 3? :)
> > 
> > G'luck,
> > Peter
> > 
> > -- 
> > Peter Pentchev	roam@ringlet.net	roam@FreeBSD.org
> > PGP key:
> > http://people.FreeBSD.org/~roam/roam.key.asc
> > Key fingerprint	FDBA FD79 C26F 3C51 C95E  DF9E ED18
> > B68D 1619 4553
> > Do you think anybody has ever had *precisely this
> > thought* before?
> > 
> 
> > ATTACHMENT part 2 application/pgp-signature 
> 
> 
> 
> =====
> -----------------------------------------------------------
> All warfare is based on deception.
> -----------------------------------------------------------
> 
> __________________________________________________
> Do You Yahoo!?
> Sign up for SBC Yahoo! Dial - First Month Free
> http://sbc.yahoo.com
> 
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message

-- 
Chicago law prohibits eating in a place that is on fire.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020708200901.GB94197>